Weaknesses of type CWE-125
5,176 resultsLeitura fora dos limites de memória
Quando o código tenta ler dados além do tamanho alocado de um buffer, array ou estrutura de dados. O programa acessa memória que não deveria, podendo vazar informações sensíveis, causar travamento ou ser explorado para executar código arbitrário.
Example
Um validador de imagem PNG que lê o tamanho do chunk do header mas não verifica se esse tamanho é compatível com o arquivo; ao processar, lê bytes da memória adjacente, expondo dados de outras estruturas ou causando crash.
How to mitigate
Sempre validar comprimentos e índices antes de acessar buffers; usar funções seguras (strncpy em vez de strcpy, bounds checking em loops); compilar com sanitizadores (AddressSanitizer, Valgrind) para detectar em tempo de teste.
CVE-2024-25392MEDIUMAn out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.EPSS 0.3%CVE-2022-49623HIGHpowerpc/xive/spapr: correct bitmap allocation sizeEPSS 0.3%CVE-2026-11077HIGHBad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted EPSS 0.3%CVE-2024-32635HIGHA vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), TeamceEPSS 0.3%CVE-2022-43043MEDIUMGPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTimeOffset at /bifs/fielEPSS 0.3%CVE-2026-50491HIGHCode Integrity DLL (ci.dll) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-32055HIGHA vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain an out of bounds read past EPSS 0.3%CVE-2025-26441MEDIUMIn add_attr of sdp_discovery.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informationEPSS 0.3%CVE-2025-11840MEDIUMGNU Binutils ldmisc.c vfinfo out-of-boundsEPSS 0.3%CVE-2026-54592HIGHOj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested InputEPSS 0.3%CVE-2026-44064HIGHASP session ID out-of-bounds accessEPSS 0.3%CVE-2026-9913MEDIUMInappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of boundEPSS 0.3%CVE-2025-2231HIGHPDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-75369HIGHAn out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit EPSS 0.3%CVE-2023-53333HIGHnetfilter: conntrack: dccp: copy entire header to stack buffer, not just basic oneEPSS 0.3%CVE-2024-52998MEDIUMSubstance3D - Stager | Out-of-bounds Read (CWE-125)EPSS 0.3%CVE-2022-20604MEDIUMIn SAECOMM_SetDcnIdForPlmn of SAECOMM_DbManagement.c, there is a possible out of bounds read due to a missing bounds check. This could lead EPSS 0.3%CVE-2025-3160MEDIUMOpen Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-boundsEPSS 0.3%CVE-2025-10883HIGHCATPRODUCT File Parsing Out-of-Bounds Read VulnerabilityEPSS 0.3%CVE-2025-5200MEDIUMOpen Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 out-of-boundsEPSS 0.3%